logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-29885

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-29885

Description:
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.
Last updated date:
04/06/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/30/2022
Reference url to background

https://github.com/4ra1n/CVE-2022-29885

Type:
exploit
Confidence:
HIGH
Date of publishing:
06/30/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/01/2022
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2026

Privacy Policy